SQL injection vulnerability in Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Metrics
Affected Vendors & Products
References
History
Wed, 18 Feb 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Schneider Electric
Schneider Electric wonderware Information Server Portal |
|
| CPEs | cpe:2.3:a:schneider_electric:wonderware_information_server_portal:4.0_sp1:*:*:*:*:*:*:* cpe:2.3:a:schneider_electric:wonderware_information_server_portal:4.5:*:*:*:*:*:*:* cpe:2.3:a:schneider_electric:wonderware_information_server_portal:5.0:*:*:*:*:*:*:* cpe:2.3:a:schneider_electric:wonderware_information_server_portal:5.5:*:*:*:*:*:*:* |
|
| Vendors & Products |
Schneider Electric
Schneider Electric wonderware Information Server Portal |
Fri, 31 Oct 2025 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Schneider Electric Wonderware SQL Injection | |
| References |
|
Status: PUBLISHED
Assigner: icscert
Published: 2014-08-28T01:00:00.000Z
Updated: 2025-10-31T23:17:37.919Z
Reserved: 2014-08-22T00:00:00.000Z
Link: CVE-2014-5399
No data.
Status : Deferred
Published: 2014-08-28T01:55:03.653
Modified: 2025-11-01T00:15:33.110
Link: CVE-2014-5399
No data.